The readiness to bear a given risk in order to achieve objectives 1. Engineered as the highest residual band a system tier may carry before a deploy gate requires a signed acceptance.
- Developed in
- ch. 13, Risk appetite and tolerance, compiled into gates
- Chapters
- ch. 13, Risk Management
- Contrast with
- Risk appetite
- Source
- 1 numbered reference, listed below
Commonly confused
Risk appetite versus Risk tolerance
- Risk appetite
- How much risk, and of which kinds, an organisation is prepared to take on in pursuit of its objectives.
- Risk tolerance
- The readiness to bear a given risk in order to achieve objectives.
The differenceHow much risk the organisation will take on overall, against the residual band one system may carry.
Why it mattersAppetite is a board statement compiled to data; tolerance is the threshold a deploy gate reads.
Where it is used
3 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 13 · Risk Management Risk, defined for engineers 8 mentions
- 14 · Development The use-case record 1 mention
- 22 · Principles & Standards NIST AI RMF 1.0 in depth 1 mention
Patterns that use this term
One pattern page uses the term.
- Use-Case Intake & Risk Tiering 1 mention
Related terms
Sources
- [1] Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (risk tolerance and residual risk; seven trustworthy characteristics; transparency answers "what happened", explainability "how", interpretability "why"; MAP 1.1 intended purposes; MANAGE 1.1 go/no-go determination; profiles). NIST. 2023-01-26. https://doi.org/10.6028/NIST.AI.100-1 (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .